sdecoret - stock.adobe.com

Guest Post

Beyond discovery: The real shadow AI challenge

IT teams can now identify shadow AI tools, but remediation doesn't scale. Managing hundreds of niche AI tools requires faster approvals and distributed governance.

Does the traditional shadow IT playbook work for shadow AI? No, but not for the reasons most imagine.

With the right technology stack, IT teams can still discover and inventory a large share of the shadow AI tools in their environments. What doesn't scale is acting on what they find.

According to a 2026 Resume Now survey of more than 1,000 U.S. workers, 76% have sourced their own AI tools rather than using employer-provided options. The volume in use across large organizations is severely underestimated and growing fast.

The discovery process

Most of the public discussion and research on shadow AI focuses on discovery. Shadow AI poses distinct challenges here, including AI features shipping inside already-approved SaaS tools, unauthorized use of approved AI tools, unvetted browser extensions and AI-enabled integrated development environment plugins -- all of which generate far less detectable activity than traditional shadow IT ever did.

The traditional shadow IT discovery stack comprises network monitoring, web proxies, cloud access security brokers and DNS logging. With these tools, IT teams can effectively inventory the desktop and web applications in use across their organizations. But visibility generally ends there -- teams can see what tools are being used, not what data is flowing through them. And few businesses continuously monitor their existing vendors for newly released AI features that might change how data is handled.

This lack of visibility has pushed many IT teams and vendors toward a new perimeter that isn't defined by the network but rather by the end user's browser and device. An emerging category of tools, described as workforce AI security or AI usage security, moves beyond identifying which application a person can access to get visibility into interactions between users and AI systems. These tools monitor the content of prompts, the sensitivity of data being shared and whether AI features within approved tools have changed how data is handled. This functionality is appearing in both established platforms, such as Microsoft Purview, and newer entrants, such as Check Point's Workforce AI Security product.

Compiling a list of shadow AI tools is … the easy part. The harder question is what happens next?

Gaps remain, of course. Privacy regulations such as the EU's GDPR could restrict prompt-level monitoring in certain jurisdictions. Desktop AI applications might evade browser-based monitoring tools entirely, even on managed devices. And personal devices are largely invisible; an employee can pull company data onto their phone and run it through any consumer AI app with no enterprise tool ever seeing it.

That said, on managed devices and corporate networks, discovery is becoming increasingly manageable. IT teams that haven't yet explored the newer generation of workforce AI security tools should. The coverage they offer is better than most organizations realize.

The block-and-tackle approach

Compiling a list of shadow AI tools is, believe it or not, the easy part. The harder question is what happens next?

The standard post-discovery process looks roughly the same in most organizations:

  • Identify an unsanctioned tool.
  • Assess its risk.
  • Reach out to the team using it.
  • Understand their business case.
  • Make a decision – sanction it, replace it or block it.

This is the blocking-and-tackling model, and it can work at a basic level.

But each tool requires its own, often highly manual remediation project. In practice, a single discovery can mean weeks of work, tracking down who's using the tool; evaluating whether it can be sanctioned; if not, finding a replacement; and communicating the decision back to affected users.

Some steps, such as flagging tools above a certain risk threshold or notifying users automatically, can be streamlined. But as most IT leaders acknowledge, simply removing a tool without providing an adequate replacement can push employees toward another workaround.

Blocking and tackling doesn't scale in the AI era. Much of the current IT governance focus centers on a handful of general-purpose models -- ChatGPT, Claude and Gemini -- as though managing those platforms is the bulk of the problem. But increasingly, employee AI use is shifting to vertical tools: purpose-built applications, mostly SaaS-based, for contract review, content preparation, financial modeling, customer support and dozens of other functions.

Many of these niche tools have AI so deeply embedded that users often don't think of them as AI tools. And, because AI has dramatically reduced the cost of building software, new vendors are constantly targeting narrower use cases. Evaluating a few major platforms might be manageable, but evaluating hundreds or thousands of specialized tools that small teams are using to solve problems IT might not even understand isn't manageable.

In many companies, employees often assume IT will say no, so they never ask.

The blocking-and-tackling model is still necessary for the highest risk discoveries -- tools handling customers' personally identifiable information, regulated data and proprietary source code. But as the primary strategy for managing shadow AI, it isn't sufficient.

Organizational changes

Blocking and tackling will only go so far. To manage shadow AI at the scale most organizations are facing, real process and organizational changes are needed. According to a National Cybersecurity Alliance study, 58% of AI users received no training in data security or privacy risks associated with the technology. A majority of workers lack clear guidance on AI use policies. In many companies, employees often assume IT will say no, so they never ask.

Three areas deserve attention.

Faster, leaner approval processes

Today, model risk management can take up to a year, and standard tools can take weeks or months to approve. Meanwhile, an employee can sign up for a free AI tool in under a minute. IT teams need to close that gap with more self-serve approval pathways for tools that don't touch critical data, automated decisions where possible and streamlined risk reviews for everything else.

The review criteria should be simple and consistent. It should focus on what data flows into the tool, the vendor's data retention and training policies, and the data classification that applies. The data alone doesn't determine risk. A use involving nonsensitive data can still be consequential if it affects customer decisions, pricing or production systems. Data governance should be embedded into the approval criteria.

More distributed IT governance

A clear insight from organizational economics is that decentralized units respond better to changes in their markets. In practice, this means pushing AI governance decisions closer to where tools are being adopted -- not through additional AI committees, but through embedded technology professionals, department-level accountability for AI risk or designated AI leads within business units. Central IT sets the framework and escalation thresholds, and business units operate within it.

Security education

Security education should focus narrowly on what data can and can't be shared with external AI tools, and what types of tools carry the most risk. Phishing awareness programs can take years of sustained effort but ultimately change employee behavior by keeping the message simple and repeatable. Shadow AI education should aim for the same.

The companies best positioned to capitalize will be the ones that build clear guardrails around low-risk experimentation while focusing security resources on the uses that could cause real harm.

These three shifts won't eliminate shadow AI. But they move the organization from case-by-case remediation to a more comprehensive model for managing AI risks at scale.

What's at stake

Organizations with high levels of shadow AI incurred average breach costs $670,000 higher than those with little or no shadow AI, according to IBM's 2025 Cost of a Data Breach Report.

But the financial risk is only part of the picture. The pace of AI innovation is accelerating, and so is the opportunity cost of failing to govern it well. The companies best positioned to capitalize will be the ones that build clear guardrails around low-risk experimentation while focusing security resources on the uses that could cause real harm. The discovery tools exist. The harder work is everything that follows.

John Frechette is the founder of Sourced Economics, a research and advisory firm focused on enterprise digital transformation. Dr. Suzannah Hicks is senior manager of the AI Center of Excellence at Ferguson, a Fortune 500 company. The views expressed by Dr. Hicks are her own.

Next Steps

Shadow AI: How CISOs can regain control

Prevent and manage cloud shadow AI with policy and tools

Shadow AI in healthcare: The hidden risk to data security

Dig Deeper on AI Ethics & Governance